{"version":"1.0.0","segments":[{"startTime":0.16,"endTime":3.92,"body":"Welcome back, tech enthusiasts. I'm your host, Greg Doig, and thanks for tuning"},{"startTime":3.92,"endTime":7.68,"body":"in. Today we're talking about a sophisticated new phishing campaign"},{"startTime":7.68,"endTime":11.32,"body":"that's causing quite a stir in the cybersecurity world. And"},{"startTime":11.32,"endTime":14.24,"body":"here's the scary part. It can bypass Microsoft"},{"startTime":14.24,"endTime":17.88,"body":"365 multi-factor authentication. Yep."},{"startTime":17.88,"endTime":21.68,"body":"Even if you're doing everything right, attackers may still be able to sneak in."},{"startTime":22.16,"endTime":26.0,"body":"Let's unpack what's going on here. Most phishing attacks try to"},{"startTime":26.0,"endTime":29.43,"body":"steal your username and password. Basic stuff. And with"},{"startTime":29.43,"endTime":33.27,"body":"MFA turned on, you've usually got a strong safety net. But"},{"startTime":33.27,"endTime":37.07,"body":"this new attack, well, it plays by a different rulebook. Threat"},{"startTime":37.07,"endTime":40.048,"body":"actors are now abusing something called the OAuth"},{"startTime":40.212,"endTime":43.83,"body":"2.0 device authorization grant flow, often"},{"startTime":43.909,"endTime":47.67,"body":"just called the device code flow. Normally, this is used"},{"startTime":47.67,"endTime":51.15,"body":"legitimately by devices like smart TVs or command line"},{"startTime":51.15,"endTime":54.93,"body":"tools that don't have a full sign-in interface. Here's the"},{"startTime":54.93,"endTime":58.41,"body":"twist. The attackers send you an actual Microsoft"},{"startTime":58.41,"endTime":62.25,"body":"page, not a fake one, and ask you to enter a device"},{"startTime":62.25,"endTime":66.09,"body":"code they provide. Once you do that and complete your MFA, the"},{"startTime":66.09,"endTime":69.81,"body":"attackers intercept the resulting authentication tokens in real time."},{"startTime":70.37,"endTime":73.97,"body":"That means they get access without ever touching your password. And"},{"startTime":73.97,"endTime":77.41,"body":"worse, they get persistent access to Outlook, Teams,"},{"startTime":77.41,"endTime":81.09,"body":"OneDrive, SharePoint, and even some admin-level capabilities."},{"startTime":81.98,"endTime":85.62,"body":"The campaign has been active since late 2025 and"},{"startTime":85.62,"endTime":89.42,"body":"is heavily concentrated in North America, especially the"},{"startTime":89.42,"endTime":92.86,"body":"United States. And the industries being targeted, no"},{"startTime":92.86,"endTime":96.46,"body":"surprise here, tech, manufacturing, financial services."},{"startTime":97.1,"endTime":100.94,"body":"These are sectors where attackers know the data is valuable and the"},{"startTime":100.94,"endTime":104.7,"body":"access is lucrative. So how can you spot one of"},{"startTime":104.7,"endTime":107.82,"body":"these attacks? Here are some red flags to watch for."},{"startTime":108.36,"endTime":112.2,"body":"You're suddenly asked to enter a device code to verify your identity."},{"startTime":112.52,"endTime":116.24,"body":"An email or phone call claims to be from IT and pressures you to"},{"startTime":116.24,"endTime":119.68,"body":"log in immediately. You get an MFA prompt you didn't"},{"startTime":119.68,"endTime":123.44,"body":"initiate, or a workflow feels off, especially if it"},{"startTime":123.44,"endTime":127.16,"body":"appears out of nowhere. This attack relies heavily on social"},{"startTime":127.16,"endTime":131.0,"body":"engineering, timing, and credibility. The attacker's goal is"},{"speaker":"simple","startTime":131.0,"endTime":133.96,"body":"make you think you're doing something legitimate."},{"speaker":"simple","startTime":134.99,"endTime":138.03,"body":"Now here's how you can protect yourself and your organization."},{"speaker":"simple","startTime":138.59,"endTime":142.11,"body":"Ready? 1, never enter a device code unless you"},{"speaker":"simple","startTime":142.11,"endTime":145.71,"body":"personally initiated it. 2, decline MFA"},{"speaker":"simple","startTime":145.71,"endTime":149.55,"body":"prompts you didn't request. 3, verify URLs"},{"speaker":"simple","startTime":149.55,"endTime":153.15,"body":"before logging in, even if they look familiar. 4, report"},{"speaker":"simple","startTime":153.15,"endTime":156.35,"body":"suspicious emails immediately. Don't wait."},{"speaker":"simple","startTime":156.91,"endTime":160.35,"body":"5, if you think you might have interacted with one of these attacks,"},{"speaker":"simple","startTime":160.94,"endTime":164.58,"body":"contact IT as soon as possible. Token theft can be"},{"speaker":"simple","startTime":164.58,"endTime":168.14,"body":"reversed, but only if we know it's happened. This phishing"},{"speaker":"simple","startTime":168.14,"endTime":171.98,"body":"campaign is a perfect reminder that cyber threats continue to evolve,"},{"speaker":"simple","startTime":172.3,"endTime":175.94,"body":"and even our best defenses can be manipulated. But with"},{"speaker":"simple","startTime":175.94,"endTime":179.66,"body":"awareness, vigilance, and quick reporting, we can stay ahead of"},{"speaker":"simple","startTime":179.66,"endTime":183.5,"body":"attacks like these. If you found this helpful, make sure to subscribe,"},{"speaker":"simple","startTime":183.5,"endTime":187.27,"body":"share this episode with your friends and teammates, and help someone else"},{"speaker":"simple","startTime":187.27,"endTime":190.99,"body":"stay secure today. I'm Greg Doig. Once again, thanks for listening."},{"speaker":"simple","startTime":191.07,"endTime":194.83,"body":"Stay safe, stay skeptical, and I'll talk to you soon."}]}